Autonomy is not a feature you turn on. It is a level of trust an agent earns, one decision class at a time, against evidence you collected yourself.
Every vendor deck I see right now ends on the same slide: the autonomous SOC. Agents that triage, investigate, decide, and remediate while your analysts sleep. It is a compelling picture. It is also, in most environments, a liability waiting to be discovered during an incident.
I am not a skeptic of AI in security. I have spent the better part of two decades building it. At MasterCard I helped stand up one of the first AI fraud detection systems in the industry. At Intuit, where I built and led the Business Information Security Organization, we deployed security-solving genAI agents that reduced the time engineers spend fixing repetitive, duplicative issues, and we cut QuickBooks spam fraud by more than 98 percent in under five months using NLP, machine learning, and generative AI. I believe in this technology because I have shipped it and measured it.
That experience is exactly why I push back on "autonomous" as a starting point. Autonomy is not a feature you turn on. It is a level of trust an agent earns, one decision class at a time, against evidence you collected yourself.
An agent that recommends vs. an agent that acts
Here is the distinction that matters. There is a wide gap between an agent that recommends and an agent that acts. The first compresses analyst time. The second compresses analyst judgment. Both are valuable, but they carry completely different blast radii. A bad recommendation costs a few minutes of review. A bad automated remediation — a revoked credential during a sales close, a quarantined production workload, an account locked at the worst possible moment — costs you the business's trust in the security team. I have spent my career trying to reduce customer friction while increasing protection. Few things create more friction, internal or external, than security automation that acts confidently and wrongly.
So how do you actually get to autonomy without betting the company on a demo?
Grant trust one stage at a time
Start by separating the agent's job into stages and granting trust to each one independently. Detection, enrichment, correlation, recommendation, and action are not a single capability. They are five. An agent can be fully autonomous at enrichment — pulling context, stitching signal across cloud and SaaS and identity — long before it earns the right to take an action on its own. At Intuit, the agentic work that paid off fastest was the unglamorous middle of that pipeline: removing the repetitive toil that buries analysts, not replacing the call at the end of it.
Instrument the agent like an employee on probation
Second, instrument the agent like an employee on probation, because that is what it is. When I onboard a new analyst, I do not hand them the keys to production on day one. I give them scoped work, I review their output, and I expand their authority as they demonstrate judgment. An AI agent deserves exactly the same discipline and exactly the same paper trail. Every decision needs to be logged, attributable, and reconstructable after the fact. If you cannot answer "why did the agent do that" during a post-incident review, the agent has too much authority and too little accountability.
Decide your rollback story first
Third — and this is the one most teams skip — decide your rollback story before you grant the action. Agentic remediation without a tested, fast, well-understood undo is not automation. It is a new and creative way to cause an incident. The question I ask any team proposing automated action is simple: when this agent is wrong, and it will be, how fast can we reverse it, and who gets paged? If the answer is fuzzy, the agent stays in recommend-only mode.
Outcome metrics, not activity metrics
There is also a measurement trap worth naming. The agentic SOC is being sold on alert volume and time-to-triage, and those are real gains. But they are input metrics. The outcomes that actually matter are adversary resilience and reduced material risk. At Intuit we reduced fraud 40 percent year over year while improving the customer experience — that pairing is the whole point. An agent that closes tickets faster but does not measurably move your risk posture is theater with good throughput. Hold your AI investments to outcome metrics, not activity metrics, the same way you would hold any other line item.
None of this is an argument for going slow. It is an argument for going fast in the right order. The teams that will win with the agentic SOC are not the ones who flip on autonomy first. They are the ones who build the trust, the telemetry, and the rollback discipline that let them flip it on safely, and then expand that autonomy aggressively because they have earned the confidence to do so.
The autonomous SOC is coming, and I want it here. But "autonomous" is the destination, not the on ramp. Earn it one decision class at a time, prove it with evidence you gathered, and you will get there faster than the teams who skipped straight to the last slide.
FAQ
How do I roll out agentic SOC capabilities gradually?
Separate the agent's job into stages — detection, enrichment, correlation, recommendation, and action — and grant trust to each one independently. An agent can be fully autonomous at enrichment long before it earns the right to act on its own.
Should AI agents take autonomous action in the SOC?
Only after they have earned it. A bad recommendation costs a few minutes of review; a bad automated remediation costs the business's trust in the security team. Expand authority the way you would for a new analyst: scoped work, reviewed output, a full paper trail.
What must be in place before enabling automated remediation?
A tested, fast, well-understood rollback. When the agent is wrong — and it will be — you need to know how fast you can reverse it and who gets paged. If the answer is fuzzy, the agent stays in recommend-only mode.
